CVE-2016-0765

MEDIUM

WordPress eShop plugin 6.3.14 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.

Scores

CVSS v3 6.1
EPSS 0.0030
EPSS Percentile 52.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-79
Status published

Affected Products (2)

elfden/eshop_plugin
n/a/n/a

Timeline

Published Jan 23, 2017
Tracked Since Feb 18, 2026